Tech & Cybersecurity Risk Lead

2 days ago


Singapore GXS Bank Full time

**About the Team**:
You will join the dynamic Tech and Cyber Risk Governance team, operating as a vital second line of defence (2LoD) function. We are the dedicated guardians of GXS Bank's digital resilience, responsible for establishing, maintaining, and overseeing robust governance frameworks to effectively manage technology, cybersecurity, and related third-party risks across the Bank and subsidiaries. With a footprint in the region, our team plays a pivotal role in identifying, assessing, mitigating, and monitoring technology and cyber risks, whether they originate from internal projects, existing systems, or external partnerships. We collaborate extensively across Technology, Operations, Business Units, and other control functions to ensure the Bank and subsidiaries operate securely, comply with regulatory requirements, and confidently pursue innovative goals. We champion a proactive risk culture and value deep expertise, critical thinking, continuous improvement, and technical proficiency in developing and enhancing our GRC capabilities.

**Key Responsibilities**:
As a senior member of the Tech and Cyber Risk Governance team, you will play a key role in shaping and executing the Bank's strategy for managing technology and cyber risk. Your expertise is crucial for safeguarding the Bank's resilience, ensuring regulatory compliance, and enabling secure innovation across the region, with a strong emphasis on technical risk assessment across diverse initiatives and developing our ServiceNow GRC platform.

1. Governance, Risk Framework & Acceptance:

- Develop, implement, and maintain the Bank's comprehensive technology and cyber risk frameworks, policies, and standards, ensuring alignment with regulatory requirements (MAS TRM & Outsourcing Guidelines, etc.) and best practices.
- Drive adherence to these frameworks and standards across business and technology functions for both internal projects and third-party engagements.
- Oversee and perform formal risk assessments and manage the risk acceptance process according to Bank policies and risk appetite.

2. Risk Assessment & Management:

- Drive technology and cyber cyber key metrics (Key Risk Indicators (KRIs), etc.) definition and reporting against the Bank's risk appetite.
- Contribute to and oversee aspects of the Third Party Risk Management (TPRM) process from a technical security perspective, as part of a holistic risk management approach.
- Assess the design and operating effectiveness of technology and cyber controls within internal environments and third-party services, determine residual risks arising from control failures, and recommend necessary remediation actions.
- Maintain a risk register of all residual risk acceptances with implications for technology and cyber risks.
- Proactively track and monitor the implementation of agreed-upon technology and cyber risk mitigation measures and conduct effectiveness reviews to ensure risk reduction to acceptable levels.
- Engage in technology and cyber risk governance activities through regular participation in and reporting updates to committees, managements, and working groups as required.

3. Technical Security Solutions & GRC Platform Development:

- Conduct in-depth technical validation of security controls, architecture, and evidence for both internal systems/projects and third-party solutions (SOC 2 & ISO reports, pen test reports, architectural diagrams, code review summaries etc.).
- Plan, lead, and execute technical security assessments, including potential onsite reviews for critical internal systems or third-party locations; document findings and drive remediation.
- Lead the design, development, configuration, and enhancement of GRC solutions, particularly within the ServiceNow GRC module (e.g., Policy and Compliance, Risk Management, Vendor Risk Management), to automate and improve risk management processes, reporting, and workflows.
- Utilize technical development skills (e.g., scripting, API integration, light development) to build and maintain custom GRC functionalities, integrations with other security tools, and dashboards within ServiceNow or other supporting platforms.
- Design and enhance technical assessment methodologies, tooling, and procedures; explore/evaluate GenAI tools to improve assessment efficiency and depth.
- Identify, analyze, document technical risks/gaps; collaborate on and track effective remediation plans.

4. Stakeholder Engagement & Regulatory Compliance:

- Serve as a key technical security SME for tech and cyber risk matters, providing pragmatic guidance to internal project teams, technology owners, and business units.
- Collaborate with stakeholders (Procurement, Legal, Technology, Business Units, etc.) to embed security requirements into project lifecycles, internal development processes, and third-party contracts.
- Manage tech/cyber regulatory obligations, track compliance, report non-conformities, and support incident reporting.
- Provide mentorship and u



  • Singapore JPMorganChase Full time

    Tech Risk Engagement Lead, Cybersecurity Step into the role of Tech Risk Engagement Lead and lead the forefront of technological innovation and security. This pivotal position offers the unique opportunity to influence and shape our approach to cyber threats and compliance, balancing progressive digital transformation with robust risk management. Your...


  • Singapore JPMorgan Chase & Co. Full time

    Tech Risk Engagement Lead, Cybersecurity Job Identification Job Category Technology Risk & Services Business Unit Corporate Sector Posting Date 09/19/2025, 01:38 AM Job Schedule Full time Job Shift Day Job Description Step into the role of Tech Risk Engagement Lead and lead the forefront of technological innovation and security. This pivotal position offers...


  • Singapore ST ENGINEERING INFO-SECURITY PTE. LTD. Full time $120,000 - $240,000 per year

    Position Summary Do you have a passion for both leading cutting-edge cybersecurity initiatives and guiding organizations to secure their critical operational technology (OT)/internet of things (IoT)? We're seeking a highly skilled Senior Tech Lead with a strong consultancy technical mindset to lead and manage our projects. In this dynamic role,...


  • Singapore Krisvconsulting Services Pte Ltd Full time

    Responsibilities: Implement IT risk management frameworks, policies, and compliance checksMaintain cybersecurity policies, vendor governance, and system criticality frameworksModernize oversight via emerging tech and real-time risk tracking toolsEnsure secure SDLC and risk assessments during IT development lifecycleConduct regular audits to ensure security...


  • Singapore SEKURO OPERATIONS PTE. LTD. Full time

    **About the Role** As a GRC Analyst, you’ll be at the forefront of our cybersecurity initiatives, working closely with business and tech teams to: Conduct cybersecurity risk assessments using leading global frameworks Help shape cybersecurity roadmaps and policies aligned with real-world business risks Identify and analyse IT and business operational...


  • Singapore Pfizer Full time

    Senior Automation Engineer - AMPS page is loaded## Senior Automation Engineer - AMPSlocations: Singapore - Tuastime type: Voltijdsposted on: Vandaag geplaatstjob requisition id: ## Pfizer Singapore is recruiting permanent employees for manufacturing site expansion of PFIZER ASIA MANUFACTURING PTE LTD (PAMPL) in Singapore.# # **Why Patients Need You**Whether...


  • Singapore Sopra Steria I2S Singapore PTE. LTD. Full time

    **Company**: Sopra Steria is a listed European tech leader specializes in Consulting, Digital Service, and Software. We have 60,000 employees worldwide located in different regions (Europe, North America and Asia), whereby Singapore is the HQ for APAC. EvaGroup Asia Pacific is part of Sopra Steria I2S APAC, in charge of Infrastructure, Cloud and...


  • Singapore Pfizer Full time

    Description Join to apply for the Senior Automation Engineer - AMPS role at Pfizer Pfizer Singapore is recruiting permanent employees for manufacturing site expansion of PFIZER ASIA MANUFACTURING PTE LTD (PAMPL) in Singapore. Overview Why Patients Need You Whether you are involved in the design and development of manufacturing processes for products or...


  • Singapore Assurity Trusted Solutions Full time

    Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a...


  • Singapore Assurity Trusted Solutions Pte Ltd Full time

    Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade, ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, authentication services, governance and assurance services as well as managed processes. In a...